Secure On-Premise Secrets Replication in Cloud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, sensitive information is vulnerable to security threats due to its transfer over networks, and existing methods struggle with secure sharing and replication between servers, especially when new servers need access or when information is updated, leading to potential exposure and security vulnerabilities.
Innovation Solution
A method and system for secure sharing of sensitive information involve determining the trustworthiness of entities, using digital certificates, and encrypting information with public and private key pairs, ensuring that only trusted entities can access and decrypt the sensitive data, thereby preventing unauthorized access and storage in untrusted environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If sensitive information is transferred over computer networks in cloud computing environments, then data processing and service accessibility are improved, but security vulnerability to eavesdropping and interception increases
Solution Approach 1:
The patent creates encrypted copies of sensitive information that can be securely transmitted across networks. Instead of transmitting plaintext sensitive data, the system generates encrypted replicas that maintain data integrity and confidentiality while enabling cloud-based processing and service accessibility.
Solution Approach 2:
The patent introduces encryption algorithms and security protocols as intermediary layers between the sensitive information and network transmission. These intermediaries transform the data into secure formats, allowing network communication while protecting against eavesdropping and interception threats.
2Adaptability or versatility
If sensitive information is shared between multiple servers for replication and access, then service continuity and accessibility are improved, but exposure risk and security vulnerabilities increase
Solution Approach 1:
The patent applies different security measures to different servers and data copies. Each server receives appropriately encrypted versions of sensitive information with access controls tailored to its specific role and trust level. This localized security approach enables multi-server replication while minimizing overall exposure risk.
Solution Approach 2:
The patent creates multiple encrypted copies of sensitive information that can be distributed across servers. Each copy is secured with encryption keys and access controls, allowing service continuity and accessibility across multiple servers while maintaining security through the use of encrypted replicas rather than plaintext distribution.
3Device complexity
If existing methods are used for sharing sensitive information between servers, then implementation simplicity is maintained, but security strength and protection against unauthorized access are insufficient
Solution Approach 1:
The patent replaces simple, mechanical security methods (such as basic access controls or plaintext sharing) with cryptographic mechanisms. Encryption algorithms, digital signatures, and key management systems substitute for weaker security approaches, providing stronger protection while maintaining reasonable implementation complexity through standardized cryptographic protocols.
Data Source
AI summary
Systems and methods for secure sharing of sensitive information in a computing environment. The methods comprise, by a first entity of a first computing environment receiving sensitive information of the first computing environment, receiving a request to share the sensitive information from a second entity of the first computing environment, and determining whether the second entity is a trusted entity included in a list of trusted entities held by a configuration service associated with a second computing environment. If the second entity is not a trusted entity, determining whether the second entity can establish trust by validating a subscription of the second entity with a directory service, and validating a digital certificate corresponding to the second entity with a certificate authority. If the second entity can establish trust or is a trusted entity, sharing the sensitive information with the second entity so as to enable operation of the second entity.


